- EPSS 20.97%
- Published 26.04.2006 20:06:00
- Last modified 03.04.2025 01:03:51
Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching ...
CVE-2006-0002
- EPSS 56.18%
- Published 10.01.2006 22:03:00
- Last modified 03.04.2025 01:03:51
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulatio...
- EPSS 7.15%
- Published 02.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
- EPSS 21.36%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to autom...
- EPSS 11.27%
- Published 23.11.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characte...
CVE-2004-0200
- EPSS 76.69%
- Published 28.09.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to...
- EPSS 53.57%
- Published 18.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote sit...
- EPSS 53.57%
- Published 18.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on pred...
- EPSS 18.68%
- Published 18.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's set...
CVE-2004-0204
- EPSS 77.62%
- Published 06.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1....